Backdoor.Win32.VB.mi
(Backdoor.Win32.VB.mi)

by ?

Original name unknown.

Written in Visual Basic

more in this category

 

 


dropped file:
c:\WINDOWS\system32\JAVASCSYS.EXE
size: 1,720,320 bytes 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Javascsys"
data: C:\WINDOWS\SYSTEM32\JAVASCSYS.EXE 

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "Javascsys"
data: C:\WINDOWS\SYSTEM32\JAVASCSYS.EXE 




tested on Windows XP
October 20, 2005

MegaSecurity